← Back to list

BTLO — Cerulean — Walkthrough

By Owais Ali Khan

Owais Ali Khan · 2026-02-09 03:43 · 7 claps · 4.2 min read
#btlo #blueteamlabsonline #blue-team-training #cybersecurity #digital-forensics
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

BTLO — Cerulean — Walkthrough

By Owais Ali Khan

QUESTION 1

SOLUTION

First, I reviewed the Magnet report provided with the lab. I navigated to Chrome Web History, where I searched for the keyword “mail”. This revealed the event where Jane clicked a malicious IT support email.

The report only showed limited information about this event, so I proceeded to analyze Jane’s Chrome browser history directly. The Chrome history file is raw data and not easily readable. To convert it into a human-readable format, I used the Hindsight tool.

Hindsight parsed the raw Chrome artifacts and generated a readable file named History-Owais.xlsx, which I then opened using Timeline Explorer. Within Timeline Explorer, I searched for the keywords “mail” and “support” in the relevant columns. This allowed me to identify the exact time when Jane received and interacted with the malicious email.

ANSWER 1

QUESTION 2:

SOLUTION:

After analyzing the browser traffic logs, I observed that Google Drive had the highest number of entries. The total traffic count associated with Google Drive was 108, making it the most frequently accessed service.

ANSWER 2

QUESTION 3:

SOLUTION:

To identify the ITM (Insider Threat Matrix) ID, I focused my investigation on Google Drive activity, as it accounted for the highest traffic volume. By reviewing multiple Google Drive entries, I was able to determine the relevant ITM identifier.

ANSWER 3

QUESTION 4:

SOLUTION:

I navigated to the User Accounts section in the report. There, I reviewed Jane’s account details and identified the required information from the account description.

ANSWER 4

QUESTION 5:

SOLUTION

Initially, I checked the Installed Programs section and identified the entry for Slack, including its entry date and time. However, to determine the exact installation timeline, I again used Timeline Explorer to analyze the previously generated History-Owais.xlsx file.

This allowed me to correlate Slack-related activity with browser timestamps for accurate installation context.

ANSWER 5

QUESTION 6:

SOLUTION:

To identify an unofficial URL as evidence, I opened History-Owais.xlsx in Timeline Explorer once more. I located a login-related URL, which served as supporting evidence for this question.

ANSWER 6

Question 7:

Solution:

I navigated to the Remote Desktop section of the report. There, I identified evidence of an RDP connection associated with Jane’s system.

Answer 7

QUESTION 8:

SOLUTION:

Following the hint provided in the lab, I navigated to the Windows Defender log path using File Explorer. I opened the relevant MPLog_201… file and searched for the keywords “Project” and “Cerulean”.

This search revealed the required information to answer the question.

Then I searched “Project and Cerulean” and I got the Answer.

ANSWER 8

LAB COMPLETED


메타데이터
post_id
28e2c2f150ce
slug
btlo-cerulean-walkthrough-28e2c2f150ce
url
https://medium.com/@owaisalikhan081/btlo-cerulean-walkthrough-28e2c2f150ce
canonical_url
https://medium.com/@owaisalikhan081/btlo-cerulean-walkthrough-28e2c2f150ce
author_url
https://medium.com/@owaisalikhan081
status
ok
fetched_at
2026-06-09 15:37:30